Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
1–10 of 60 posts
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#2"Hello from github,
We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure.
Have a look at this blog where we discuss alternatives"
EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to public repos
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#3Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#4Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Is there a disadvantage to banning private keys in public repos?
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#5Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Is there a disadvantage to banning private keys in public repos?
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#6Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#7Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Is there a disadvantage to banning private keys in public repos?
Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to public repos
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#8Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Is there a disadvantage to banning private keys in public repos?
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#9I assume there’s some IP based quota, but I haven’t seen a knob for that on GCP at least.
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#10Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…